Computer Science

Songyun Wu, Xiaoqing Sun, Enhuan Dong, Zhiliang Wang, Chen Zhao, Jiahai Yang

2026.1.1IEEE Transactions on Dependable and Secure Computing

DOI: 10.1109/tdsc.2025.3609834

Abstract

With increasingly sophisticated attacks in cyberspace, a growing number of security devices are deployed on the organization network to prevent attacks comprehensively. However, they produce thousands of security alerts each day, causing a severe burden on security analysts. Thus, it is increasingly concerned about capturing the significant threats from the jumble of alerts. Previous works only provided scene-specific algorithms for given applications or services, which is hard to extend to other scenarios and consequently not adequate for large organizations that deploy multiple kinds of security devices. To address this, we propose a general alert classification approach named Alert2vec. With subgraph learning methods on the Heterogeneous Information Network (HIN), Alert2vec is applicable for both network-level and host-level security devices. Specifically, Alert2vec first builds a heterogeneous Alert Intelligence Graph (AIG) to catch the correlation between different alerts. Then, a novel subgraph representation method is applied to generate alert vectors based on six graph properties that can reveal the threat level of alerts. Finally, these alert vectors are labeled with various threat levels in semi-automatic or fully automatic classification mode. Alert2vec is proven to be effective on real-world datasets, outperforming all baselines on both network-level and host-level scenarios.

Citation format

WU, Songyun, et al. Alert2vec: Eliminating alert fatigue by embedding security alerts through subgraph learning. IEEE Transactions on Dependable and Secure Computing, 2026, 23: 655–669.